VYPR
Vendor

QNAP Systems Inc.

Products
15
CVEs
277
Across products
530
Status
Private

Products

15

Recent CVEs

277
View all 277 CVEs →
  • CVE-2022-27593CriKEVSep 8, 2022
    risk 0.90cvss 10.0epss 0.88

    An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo…

  • CVE-2021-28799CriKEVMay 13, 2021
    risk 0.89cvss 10.0epss 0.78

    An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2;…

  • CVE-2024-21899CriMar 8, 2024
    risk 0.66cvss 9.8epss 0.24

    An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following…

  • CVE-2024-50387CriDec 6, 2024
    risk 0.65cvss 9.8epss 0.10

    A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: SMB Service 4.15.002 and…

  • CVE-2024-32766CriApr 26, 2024
    risk 0.65cvss 10.0epss 0.02

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build…

  • CVE-2023-23368CriNov 3, 2023
    risk 0.65cvss 9.8epss 0.19

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build…

  • CVE-2023-34976CriOct 13, 2023
    risk 0.65cvss 10.0epss 0.01

    A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.0 ( 2023/07/27 )…

  • CVE-2025-66277CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS…

  • CVE-2025-11837CriJan 2, 2026
    risk 0.64cvss 9.8epss 0.01

    An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulnerability to bypass protection mechanism. We have already fixed the vulnerability in the following version: Malware Remover…

  • CVE-2025-62849CriDec 16, 2025
    risk 0.64cvss 9.8epss 0.01

    An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297…

  • CVE-2025-59385CriDec 16, 2025
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication. We have already…

  • CVE-2017-20210CriNov 11, 2025
    risk 0.64cvss 9.8epss 0.00

    Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by internal research.

  • CVE-2025-52425CriNov 7, 2025
    risk 0.64cvss 9.8epss 0.00

    An SQL injection vulnerability has been reported to affect QuMagie. A remote attacker can exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QuMagie 2.7.0 and later

  • CVE-2024-50393CriDec 6, 2024
    risk 0.64cvss 9.8epss 0.01

    A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954…

  • CVE-2024-48862CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed the…

  • CVE-2024-32764CriApr 26, 2024
    risk 0.64cvss 9.9epss 0.00

    A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level of some functionality via a network. We have already fixed the vulnerability in the following…

  • CVE-2022-27596CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QuTS hero, QTS: QuTS hero h5.0.1.2248 build…

  • CVE-2021-28804CriJul 1, 2021
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build…

  • CVE-2021-28802CriJul 1, 2021
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build…

  • CVE-2020-2507CriFeb 3, 2021
    risk 0.64cvss 9.8epss 0.03

    The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.